An incomplete fix for CVE-2024-47778 allows an out-of-bounds read in gst_wavparse_adtl_chunk() function. The patch added a size validation check lsize + 8 > size, but it does not account for the GST_ROUND_UP_2(lsize) used in the actual offset calculation. When lsize is an odd number, the parser advances more bytes than validated, causing OOB read.
CVSS Details
- CVSS 3.1 Base Score: 5.1
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade gstreamer-plugins-goodUpgrade gstreamer1-plugins-good-debuginfoUpgrade gstreamer-plugins-good-debuginfoUpgrade gstreamer1-plugins-good-gtkUpgrade gstreamer-plugins-good-devel-docsUpgrade gstreamer1-plugins-good | May 20, 2026 | May 20, 2026 |
| Amazon_linux_2023 | — | Upgrade gstreamer1-plugins-good-debuginfoUpgrade gstreamer1-plugins-good-debugsourceUpgrade gstreamer1-plugins-good-gtkUpgrade gstreamer1-plugins-goodUpgrade gstreamer1-plugins-good-gtk-debuginfo | Apr 14, 2026 | Feb 25, 2026 |
| Debian | — | Upgrade gst-plugins-good1.0 | Jul 23, 2026 | Jul 23, 2026 |
| Freebsd | — | Upgrade gstreamer1-plugins-goodUpgrade gstreamer1Upgrade gstreamer1-plugins-uglyUpgrade gstreamer1-pluginsUpgrade gstreamer1-plugins-bad | Mar 9, 2026 | Mar 7, 2026 |
| Redhat_linux | — | No solution exists | Jul 17, 2026 | Feb 25, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub